QCS Security Advisory Desk

Network vulnerabilities and vendor patches, verified at the source.

Monitor network-edge vulnerabilities, known exploitation, affected products, mitigations, and vendor patch guidance without waiting for a weekly editorial cycle.

QCS pathSource-to-action path
  1. 01Official sourceMonitor vendors and trusted authorities.
  2. 02Verify contextCheck products, exposure, and evidence.
  3. 03Set prioritySeparate urgent action from useful reading.
  4. 04Act or learnPatch, mitigate, investigate, or prepare.

Live intelligence

See the items that can change today's patch or mitigation plan.

Priority combines source severity, known exploitation, remote attack conditions, recency, and network-edge relevance.

Critical or high16
Exploitation reported39
Vendors tracked8
Verified in 24 hours12
Showing 1-12 of 73Ordered by operational priority
Cisco critical security advisory
critical

Cisco / Priority 100

Cisco IOS XR Software Security Hardening Release: September 2026

Cisco discovered multiple security vulnerabilities in its IOS XR software during internal testing. These issues could allow attackers to cause serious problems if exploited. Cisco has released software updates to fix these vulnerabilities and strongly recommends users apply these updates promptly. There are no alternative workarounds to protect against these issues.

CVE-2026-20274CVE-2026-20275CVE-2026-20276CVE-2026-20277
Published
3 Sept 2026
CVSS
Not scored
Verified
3 Sept 2026
Review evidence and action
Cisco critical security advisory
critical

Cisco / Priority 100

Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability

A security weakness in certain Cisco Nexus 9000 Series Switches lets an attacker connect remotely without needing to log in and run harmful commands with full admin rights. This happens because specific network ports (43210 and 43211) are open by default, letting attackers send malicious data. Exploiting this could also crash a key process, forcing the device to restart. Cisco has published software updates and workarounds to protect devices.

CVE-2026-20212CiscoCisco Nexus 9000 Series Switches with Silicon One ASIC
Published
2 Sept 2026
CVSS
Not scored
Verified
3 Sept 2026
Review evidence and action
Cisco critical security advisory
critical Exploitation reported

Cisco / Priority 100

Cisco Crosswork Security Hardening Release: August 2026

Cisco has identified multiple security weaknesses in its Crosswork product line after an internal review. These issues could allow attackers to control software functionality, access protected credentials, execute harmful database commands, or manipulate files improperly. Cisco released software updates to fix these problems, and no workaround solutions are available. Users are advised to upgrade their software promptly to protect their systems.

CVE-2026-20030CVE-2026-20357CVE-2026-20358CVE-2026-20359
Published
21 Aug 2026
CVSS
Not scored
Verified
31 Aug 2026
Review evidence and action
Cisco critical security advisory
critical

Cisco / Priority 100

Cisco Secure Workload Software Security Hardening Release: August 2026

Cisco conducted an internal security review of its Secure Workload software and found several security weaknesses that could allow attackers to take control, bypass protections, or cause harmful crashes. These issues were discovered during internal testing and are not known to be exploited in the wild. Cisco has released software updates to fix these problems, but there are no temporary fixes available. Customers should update their software as soon as possible to protect their systems.

CVE-2026-20231CVE-2026-20315CVE-2026-20317CVE-2026-20318
Published
19 Aug 2026
CVSS
Not scored
Verified
19 Aug 2026
Review evidence and action
Cisco critical security advisory
critical

Cisco / Priority 100

Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

A security flaw in Cisco Secure Firewall Management Center (FMC) software lets attackers remotely bypass login controls and run harmful scripts. This could let them take full control over the system behind the firewall. The issue exists because a system process starts incorrectly when the device boots. Attackers can exploit it by sending specially crafted web requests to the device. If your firewall management interface isn’t accessible from the internet, the risk is lower. Cisco has released updates to fix this problem, but there are no other workarounds.

CVE-2026-20079Cisco Secure FirewallCisco Secure Firewall Management Center SoftwareCisco Security Cloud Control Firewall Management
Published
3 Aug 2026
CVSS
Not scored
Verified
4 Aug 2026
Review evidence and action
Cisco high security advisory
high

Cisco / Priority 100

Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability

Certain Cisco desk and video phones have a security flaw that can allow remote attackers to disable the phone by overloading its memory using specially crafted web packets. This causes the phone to stop working until it is manually restarted. To be vulnerable, the phone must be registered with Cisco Unified Communications Manager and have its Web Access feature turned on, which it is not by default. Cisco has released updates that fix this issue, but no temporary workaround fully addresses the problem.

CVE-2026-20281CiscoCisco Desk Phone 9800 SeriesCisco IP Phone 7800 Series
Published
2 Sept 2026
CVSS
Not scored
Verified
3 Sept 2026
Review evidence and action
Cisco high security advisory
high

Cisco / Priority 100

Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability

Cisco BroadWorks has a security flaw in the way it processes XML data, which could let an attacker who isn't logged in read sensitive system files. This happens because the system by default allows external references in XML files, which can be exploited by sending specially crafted messages. Cisco has released software updates to fix this issue. There is no workaround available to prevent this problem, so updating is necessary.

CVE-2026-20320CiscoBroadWorks Application Delivery PlatformBroadWorks Application Server
Published
19 Aug 2026
CVSS
Not scored
Verified
19 Aug 2026
Review evidence and action
Cisco high security advisory
high

Cisco / Priority 100

ClamAV Vulnerabilities Affecting Cisco Products: August 2026

Multiple security flaws have been found in ClamAV, an antivirus scanning component used by some Cisco software. These flaws could let an attacker send specially crafted files to disrupt the scanning process, causing it to stop working temporarily (a denial of service). Cisco has fixed these flaws in newer software versions for affected products. There are no workarounds to prevent these issues, so updating the software is the best way to stay protected.

CVE-2026-20337CVE-2026-20338CVE-2026-20339CVE-2026-20345
Published
13 Aug 2026
CVSS
Not scored
Verified
13 Aug 2026
Review evidence and action
Cisco high security advisory
high Exploitation reported

Cisco / Priority 100

Cisco Secure Firewall Management Center Software Static Credential Vulnerability

A security flaw in Cisco Secure Firewall Management Center software lets attackers log in remotely without needing to authenticate, using a built-in low-privileged account. This access can expose sensitive system data. While the account limits access rights, the vulnerability still poses significant risk, especially combined with other flaws that might allow attackers to gain higher privileges. Cisco warns that this threat is serious and recommends updating the software to fix it, as no temporary workarounds exist. Limiting public internet exposure of the management interface can reduce risk.

CVE-2026-20316Cisco Secure FirewallCisco Secure Firewall Management Center (FMC) Software
Published
11 Aug 2026
CVSS
Not scored
Verified
11 Aug 2026
Review evidence and action
Cisco high security advisory
high Exploitation reported

Cisco / Priority 100

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability

A security flaw exists in Cisco Secure Firewall devices that use the Remote Access SSL VPN service. This flaw lets an attacker who is not logged in send a special message that causes the device to restart unexpectedly, leading to service interruptions. Cisco has released updates that fix this issue, but no temporary solutions are available.

CVE-2026-20349Cisco Secure FirewallCisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCisco Secure Firewall Threat Defense (FTD) Software
Published
11 Aug 2026
CVSS
Not scored
Verified
11 Aug 2026
Review evidence and action
Cisco high security advisory
high

Cisco / Priority 100

Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability

A security flaw in Cisco IOS XE Software's Blocks Extensible Exchange Protocol (BEEP) feature lets attackers cause a device to crash and restart unexpectedly. Attackers do this by sending a specially crafted BEEP SOAP message. This leads to a denial of service (DoS), temporarily disrupting device operation. Cisco has released software updates to fix this issue, and currently, no other ways to avoid this problem exist.

CVE-2026-20263Cisco IOS XE
Published
5 Aug 2026
CVSS
Not scored
Verified
6 Aug 2026
Review evidence and action
Cisco high security advisory
high

Cisco / Priority 100

Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability

A security flaw in Cisco IOS and IOS XE software's Extensible Messaging Client Protocol (XMCP) lets attackers remotely crash affected devices. This happens when attackers send malformed XMCP packets, causing the device to unexpectedly reload and become unavailable. The attacker does not need special access or usernames to cause this issue. Cisco has released software updates to fix the problem. There are no workarounds, but a mitigation involving access control lists can limit which clients can connect, reducing risk.

CVE-2026-20301Cisco IOS XE
Published
5 Aug 2026
CVSS
Not scored
Verified
6 Aug 2026
Review evidence and action